Multiple Vendor PHPLIB Remote Script Execution Vulnerability
BID:3079
Info
Multiple Vendor PHPLIB Remote Script Execution Vulnerability
| Bugtraq ID: | 3079 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2001 12:00AM |
| Updated: | Jul 21 2001 12:00AM |
| Credit: | This vulnerability was discovered by giancarlo pinerolo <[email protected]> and submitted to BugTraq on July 21st, 2001 by "Brent J. Nordquist" <[email protected]>. |
| Vulnerable: |
PHPLib Team PHPLIB 7.2.1 PHPLib Team PHPLIB 7.2 c PHPLib Team PHPLIB 7.2 b PHPLib Team PHPLIB 7.2 |
| Not Vulnerable: |
PHPLib Team PHPLIB 7.2 d |
Discussion
Multiple Vendor PHPLIB Remote Script Execution Vulnerability
The PHP Base Library('PHPLIB') is a code library which provides support for session management in web applications. It is targeted to developers and is widely used in many web applications, so a strong possibility exists that an application may be using it without the knowledge of the administrator.
A problem in PHPLIB will allow remote attackers to submit malicious input in web requests that will cause the application to fetch and then execute scripts from another host.
This may allow for attackers to gain local access to the webserver.
The PHP Base Library('PHPLIB') is a code library which provides support for session management in web applications. It is targeted to developers and is widely used in many web applications, so a strong possibility exists that an application may be using it without the knowledge of the administrator.
A problem in PHPLIB will allow remote attackers to submit malicious input in web requests that will cause the application to fetch and then execute scripts from another host.
This may allow for attackers to gain local access to the webserver.